Vulnerability Intelligence Report
Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
CVE-2026-64645
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() or redirects() rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's hostname suffix. For a rewrite, Next.js proxies the request to that arbitrary host and serves the response from the application's origin, leading to Server-Side Request forgery. A redirects() rule configured this way is vulnerable to an Open Redirect. This issue has been fixed in versions 15.5.21 and 16.2.11.
No Active Exploit Signals
CVSS Base Score
8.3
HIGH
EPSS Probability:1.02%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-918 ↗CWE-918: Server-Side Request Forgery (SSRF)
CWE-601 ↗CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| vercel | next.js | >= 12.0.0 < 15.5.21 (affected), >= 16.0.0, < 16.2.11 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
1.020%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | GitHub, Inc. · Vendor · USA |
| Reserved | 2026-07-20T17:11:30 |
| Published | 2026-07-27T17:37:07 |
| Last Updated | 2026-07-28T14:02:21 |
Community Chatter & Buzz